CVE Tools

Human Attacker Exploits Marimo RCE, Reaches SSH Bastion in Eight Seconds

The Hacker NewsBy The Hacker News

Reported exploitedMarimoRedis

Our summary

Sysdig observed a human-operated attack exploiting CVE-2026-39987, a pre-authentication RCE flaw affecting all versions of Marimo, to obtain AWS credentials and reach an SSH bastion host in eight seconds. The activity shows how rapidly operators can turn exposed notebook services into cloud access; separately, Hunt.io reported a cryptomining campaign compromising 3,562 Redis servers through unauthenticated rogue replication and deploying XMRig.

Read at The Hacker News

The Hacker News publishes this story on its own site; we link to it rather than reprint it.

Worried this affects your company?

Discuss a security assessment of your internet-facing systems. Scope agreed before testing.

Check my exposure

We use analytics cookies to see which pages and articles actually help people. Decline and none of them run — the site works the same. What we store